Research on New Botnet Detection Strategy Based on Information Materials

Abstract

Recognized as one the most serious security threats on current Internet infrastructure, botnets with its low resource requirements have developed rapidly. How to detect botnets has become a major topic of current research. Based on existing research results, this paper proposes a new detection strategy, which solves unknown botnet detection efficiency by the behavioral characteristics of botnets. The core idea is separating static characteristic and dynamic behavior of botnet, and optimizing dynamic the parameters of dynamic behavior, and changing passive defense into active defense. According to the behavior of the attacker, this strategy can optimize behavior parameters. The proposed approach has the commonality and the expansibility, which strengthen unknown botnet defense fundamentally.